* [PATCH net] net: ep93xx_eth: Do not crash unloading module
@ 2016-12-05 3:22 Florian Fainelli
2016-12-05 20:36 ` David Miller
0 siblings, 1 reply; 3+ messages in thread
From: Florian Fainelli @ 2016-12-05 3:22 UTC (permalink / raw)
To: netdev; +Cc: davem, hsweeten, Florian Fainelli
When we unload the ep93xx_eth, whether we have opened the network
interface or not, we will either hit a kernel paging request error, or a
simple NULL pointer de-reference because:
- if ep93xx_open has been called, we have created a valid DMA mapping
for ep->descs, when we call ep93xx_stop, we also call
ep93xx_free_buffers, ep->descs now has a stale value
- if ep93xx_open has not been called, we have a NULL pointer for
ep->descs, so performing any operation against that address just won't
work
Fix this by adding a NULL pointer check for ep->descs which means that
ep93xx_free_buffers() was able to successfully tear down the descriptors
and free the DMA cookie as well.
Fixes: 1d22e05df818 ("[PATCH] Cirrus Logic ep93xx ethernet driver")
Signed-off-by: Florian Fainelli <f.fainelli@gmail.com>
---
drivers/net/ethernet/cirrus/ep93xx_eth.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/ethernet/cirrus/ep93xx_eth.c b/drivers/net/ethernet/cirrus/ep93xx_eth.c
index de9f7c97d916..9a161e981529 100644
--- a/drivers/net/ethernet/cirrus/ep93xx_eth.c
+++ b/drivers/net/ethernet/cirrus/ep93xx_eth.c
@@ -468,6 +468,9 @@ static void ep93xx_free_buffers(struct ep93xx_priv *ep)
struct device *dev = ep->dev->dev.parent;
int i;
+ if (!ep->descs)
+ return;
+
for (i = 0; i < RX_QUEUE_ENTRIES; i++) {
dma_addr_t d;
@@ -490,6 +493,7 @@ static void ep93xx_free_buffers(struct ep93xx_priv *ep)
dma_free_coherent(dev, sizeof(struct ep93xx_descs), ep->descs,
ep->descs_dma_addr);
+ ep->descs = NULL;
}
static int ep93xx_alloc_buffers(struct ep93xx_priv *ep)
--
2.9.3
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH net] net: ep93xx_eth: Do not crash unloading module
2016-12-05 3:22 [PATCH net] net: ep93xx_eth: Do not crash unloading module Florian Fainelli
@ 2016-12-05 20:36 ` David Miller
2016-12-06 20:44 ` Florian Fainelli
0 siblings, 1 reply; 3+ messages in thread
From: David Miller @ 2016-12-05 20:36 UTC (permalink / raw)
To: f.fainelli; +Cc: netdev, hsweeten
From: Florian Fainelli <f.fainelli@gmail.com>
Date: Sun, 4 Dec 2016 19:22:05 -0800
> When we unload the ep93xx_eth, whether we have opened the network
> interface or not, we will either hit a kernel paging request error, or a
> simple NULL pointer de-reference because:
>
> - if ep93xx_open has been called, we have created a valid DMA mapping
> for ep->descs, when we call ep93xx_stop, we also call
> ep93xx_free_buffers, ep->descs now has a stale value
>
> - if ep93xx_open has not been called, we have a NULL pointer for
> ep->descs, so performing any operation against that address just won't
> work
>
> Fix this by adding a NULL pointer check for ep->descs which means that
> ep93xx_free_buffers() was able to successfully tear down the descriptors
> and free the DMA cookie as well.
>
> Fixes: 1d22e05df818 ("[PATCH] Cirrus Logic ep93xx ethernet driver")
> Signed-off-by: Florian Fainelli <f.fainelli@gmail.com>
Applied, thanks Florian.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] net: ep93xx_eth: Do not crash unloading module
2016-12-05 20:36 ` David Miller
@ 2016-12-06 20:44 ` Florian Fainelli
0 siblings, 0 replies; 3+ messages in thread
From: Florian Fainelli @ 2016-12-06 20:44 UTC (permalink / raw)
To: David Miller; +Cc: netdev, hsweeten
On 12/05/2016 12:36 PM, David Miller wrote:
> From: Florian Fainelli <f.fainelli@gmail.com>
> Date: Sun, 4 Dec 2016 19:22:05 -0800
>
>> When we unload the ep93xx_eth, whether we have opened the network
>> interface or not, we will either hit a kernel paging request error, or a
>> simple NULL pointer de-reference because:
>>
>> - if ep93xx_open has been called, we have created a valid DMA mapping
>> for ep->descs, when we call ep93xx_stop, we also call
>> ep93xx_free_buffers, ep->descs now has a stale value
>>
>> - if ep93xx_open has not been called, we have a NULL pointer for
>> ep->descs, so performing any operation against that address just won't
>> work
>>
>> Fix this by adding a NULL pointer check for ep->descs which means that
>> ep93xx_free_buffers() was able to successfully tear down the descriptors
>> and free the DMA cookie as well.
>>
>> Fixes: 1d22e05df818 ("[PATCH] Cirrus Logic ep93xx ethernet driver")
>> Signed-off-by: Florian Fainelli <f.fainelli@gmail.com>
>
> Applied, thanks Florian.
Thanks! Can you also queue this one for -stable? The original commit
dates back from 2006, but it should apply with minor hunks to all
-stable kernels.
Cheers
--
Florian
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2016-12-06 20:45 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-12-05 3:22 [PATCH net] net: ep93xx_eth: Do not crash unloading module Florian Fainelli
2016-12-05 20:36 ` David Miller
2016-12-06 20:44 ` Florian Fainelli
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).